[Aide] AIDE 0.17.4 security release

2022-01-20 Thread Hannes von Haugwitz
AIDE version 0.17.4 has just been released. You can download it from https://github.com/aide/aide/releases Please ALWAYS verify the signature of a release file before using it (see README[0] for details). The most noteworthy changes between v0.17.3 and v0.17.4 are: * SECURITY FIX -

[Aide] CVE-2021-45417 - aide (>= 0.13 <= 0.17.3): heap-based buffer overflow vulnerability in base64 functions

2022-01-20 Thread Hannes von Haugwitz
Summary === David Bouman discovered a heap-based buffer overflow vulnerability in base64 functions of AIDE, an advanced intrusion detection system. An attacker could crash the program and possibly execute arbitrary code through large (<16k) extended file attributes or ACL. A local user might